🇳🇱
Site.eu
2026-09-09 09:58:44
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
debestelapp
2026-09-09 08:55:13
(6 hours ago)
Web App Attack
🇮🇳
evicky2002
2026-09-09 00:01:20
(15 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇳🇱
homeshowdomain.nl
2026-09-08 21:59:14
(17 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-07.
show less
Web App Attack
SSH
Hacking
🇺🇸
Charlesiv
2026-09-08 10:01:16
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-08T09:00:41Z
Ray ID: a37cc3a7ac66dd16
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-09-08 09:42:34
(1 day ago)
Excessive 404 errors - web scanning/probing
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 08:26:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:26:17.372225 2026] [security2:error] [pid 28498:tid 28498] [client 34.88.154.16:51006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tools.alitcogroup.com"] [uri "/.git/config"] [unique_id "ap_GqfckAIAhgY5eNLhxsQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 05:49:42
(1 day ago)
Aggressive web scan
Web App Attack
🇨🇦
zXero
2026-09-08 05:45:29
(1 day ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
🇩🇰
toolbit.online
2026-09-08 05:31:11
(1 day ago)
Detected by CrowdSec: http-probing (11 matching events in server logs)
Web App Attack
🇺🇸
kosada.com
2026-09-08 04:45:14
(1 day ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:49:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:49:46.622581 2026] [security2:error] [pid 2479:tid 2479] [client 34.88.154.16:35242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toody.com"] [uri "/.git/config"] [unique_id "ap-F2ulv2F_Qe70nr90I_QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:24:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:24:52.018444 2026] [security2:error] [pid 1489:tid 1489] [client 34.88.154.16:54744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonyv.org.villasenor.org"] [uri "/.git/config"] [unique_id "ap-ABB8BrjUJuaSsW-JvPQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:05:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:05:46.682707 2026] [security2:error] [pid 18005:tid 18061] [client 34.88.154.16:53472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonysergio.com"] [uri "/.git/config"] [unique_id "ap97in-gTxMBrNYOtlyFtgAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:39:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.154.16 (16.154.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:39:11.045283 2026] [security2:error] [pid 2769433:tid 2769433] [client 34.88.154.16:50028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonylai.com"] [uri "/.git/config"] [unique_id "ap91T55MBRMbeFjaqIIs6QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack